HoneyLabs

JA4 TLS client fingerprint

t13i1010h1_61a7ad8aa9b6_792d2c6655cb

Seen 2026-04-23 to 2026-07-24 across the retained window.

12

Source IPs

10

Networks

8

Countries

10

Ports hit

84

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

RU 3US 3LV 1IT 1LU 1DE 1BG 1FR 1

Ports targeted

Source IPCCNetworkEvents
141.94.33.148FRAS16276 OVH SAS26
80.87.206.20RUAS16276 OVH SAS22
80.87.206.19RUAS16276 OVH SAS9
130.49.187.61RUAS215540 Global Connectivity Solutions Llp6
79.124.49.146BGAS50360 Tamatiya EOOD5
157.245.2.46USAS14061 DigitalOcean, LLC4
138.124.51.186DEAS210644 Aeza Group LLC4
107.189.28.30LUAS53667 FranTech Solutions3
147.224.137.108USAS31898 Oracle Corporation2
23.175.248.21USAS16611 InfiniaHost.com1
212.77.75.20ITAS15691 Uan Company S.r.l.1
104.252.127.74LVAS56971 Cgi Global Limited1

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.